CVE-2012-0897: Irfanview

Medium severity, CVSS 6.8. EPSS: 52.2% chance of exploitation in the next 30 days.

Stack-based buffer overflow in the JPEG2000 plugin in IrfanView PlugIns before 4.33 allows remote attackers to execute arbitrary code via a JPEG2000 (JP2) file with a crafted Quantization Default (QCD) marker segment.

Affected products

  • Irfanview Irfanview: up to and including 4.32; version 1.70 only; version 1.75 only; version 1.80 only; version 1.85 only; version 1.90 only; …

Published 2012-01-20. Last modified 2026-06-16.